mtoken-im.cv
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of mtoken-im.cv
The website appears to present itself as a cryptocurrency wallet service branded as imToken. Based on the page title, meta description, and screenshot, it claims to offer a non-custodial digital wallet for assets such as Bitcoin, Ethereum, BNB, TRX, DOT, and other tokens, along with token swapping and decentralized application access. The page layout and branding suggest it is targeting users interested in mobile crypto-wallet downloads and Web3 wallet connectivity.
However, the domain name mtoken-im.cv does not appear to match the primary brand name shown on the page. The site uses imToken branding, references blockchain-related services, and includes a download path, which may indicate an attempt to distribute wallet software or direct users toward installing an application. Based on the available data, the operator is not clearly identified on the scanned page, and the domain itself appears newly registered rather than long-established.
Safety Assessment for mtoken-im.cv
This domain was flagged by 11 out of 91 security engines at the time of this scan, with multiple detections describing it as phishing or malicious. The page also appears to imitate the imToken wallet brand while using a different domain name, which may indicate a look-alike website intended to resemble an established cryptocurrency service. In addition, the domain is only 3 days old, has no established traffic ranking, and includes a download-related path that was flagged during malware scanning.
The malware scan reported 2 flagged items and also identified suspicious references involving external resources. While one mail-reputation blocklist listing was present for the domain's IP address, that signal on its own would be a weaker indicator; the more significant concern here is the multi-engine phishing consensus combined with the brand-like presentation and very recent registration. Google Safe Browsing and the checked blacklist providers were clean at the time of this scan, but that does not outweigh the broader phishing indicators.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-10-27. It appears to be served by nginx from an IP hosted by Virtual Systems LLC in Kyiv, Ukraine. DNSSEC is not enabled, and the domain uses share-dns.com / share-dns.net nameservers. The site also appears to use a modern JavaScript web application structure with multiple _next/static assets, consistent with a Next.js-style frontend.
From a security perspective, the main concerns are not the TLS setup itself but the surrounding indicators: a very new domain, unsigned DNSSEC, flagged download-related content, and multiple phishing detections from security engines. The presence of a valid SSL certificate should not be treated as proof of legitimacy, as such certificates are commonly available to both legitimate and deceptive sites.
Share your experience with this website. Was it safe? Did you encounter any issues?